I was scammed via booking.com

We talk about how would you fall for a scam, it nearly happened to me today, I have a booking in Tokyo for March through booking.com, woke up this morning tired and a bit under the weather to see a WhatsApp message supposedly from the hotel saying I needed to update my details within 12 hours of the text, only had an hour left as I hadn't looked at my phone for a while, of course went straight to the link which brought me to a booking.com look a like site with my name , hotel, dates and correct amount due, was nearly completing verify credit card details when I suddenly clicked that something didn't feel right and then noticed the number was from Brazil. I contacted the hotel and booking.com but they just said they'd look into it and contact each other. A close one!
 
Normally I wouldn't, it's just I am out of the country, we were rushing to go somewhere,I was tired and I only had a wifi connection no mobile, just caught of guard by circumstances. Still you do wonder where they got all the information from, the hotel or booking.com?
 
With this scam, it is much more likely that someone got the hotel's log in details on booking.com

A hacker or scammer is much more likely to aim for a target with multiple potential people to scam than to hack into an individuals email or laptop to try to find something to go after.

I would suggest contacting the hotel again and asking them if others have been impacted. You will get nowhere with booking.com but they should also email potential targets to warn them.
 
I use booking.com regularly with no issues, but very glad to have read this thread ss its made me aware of potential scams.
 
Last edited:
Last edited:
The scammers first phish the hotel employees, then gain access to the booking.com accomodation provider portal, through which they get access to customer data, then they target the customers.
I still don't understand how they do this when 2FA is mandatory for accommodation providers.


Setting up two-factor authentication (2FA)​

During the registration process on our platform, it’s mandatory that you set up 2FA to give your account an extra layer of protection. With 2FA activated, you'll sign in using your username and password. In addition, we'll send a PIN to your authenticated device.
If the scammers replace the 2FA authentication device with their own then presumably they'd lock the actual accommodation provider out of their own account and that would be pretty obvious to them?
 
I've contacted the hotel and booking and have now actually cancelled the hotel stay, but still got another Whatsapp message from a different number.
"
Hi dear Mr******
I am Anna, the property administrator at *** Hotel Akihabara.

We attempted to contact you today concerning your reservation from 2026-03-04 to 2026-03-06.

During a routine security audit, your card details could not be verified.

Under Booking’s new security requirements, certain reservations must undergo additional verification to confirm the legitimacy of the cardholder.

Please complete the verification at your earliest convenience to prevent cancellation.

Link*****

You may finalize the process via push notification or code.
Please note that this is not a charge — no additional payment is required.

Upon successful verification, you will receive a confirmation code.
I will remain available online for any assistance.

Best regard
 
What's the verification that they're referring to?
Presumably this is a scam/phishing message?
 
You may finalize the process via push notification or code.
Please note that this is not a charge — no additional payment is required.
This is essentially "don't worry that the push notification says it is a charge, it totally isn't".

The key to the scam is the trust they get because it looks like it is the hotel contacting you.
 
I'd expect their account would support multiple users
And multiple 2FA authentication devices?
That would severely undermine 2FA security.
The link that I posted earlier makes no mention of multiple 2FA devices and seems to imply that there can only be one.
 
And multiple 2FA authentication devices?
That would severely undermine 2FA security.
How would you expect to run a business if only one person can manage their reservations on booking.com? What if that person goes on holidays or gets hit by a bus? It's a far bigger security risk to share credentials than it is to have more than one user.
 
How would you expect to run a business if only one person can manage their reservations on booking.com? What if that person goes on holidays or gets hit by a bus? It's a far bigger security risk to share credentials than it is to have more than one user.
Where do you see that Booking.com allow accommodation providers to use more than one 2FA device? I wouldn't expect individual staff members to be using their private phones for this purpose.

Edit: ok, they seem to allow one backup device.


It’s recommended that you add a backup 2FA phone number, in case the first number isn’t accessible or is out of reach.
Maybe that's one thing that scammers are exploiting?
 
Last edited:
Biggest issue is that booking .com just don't give a damn.

A company who respect their customers would immediately investigate where the breach was likely from (most likely the hotel), make contact with them and have all passwords and authentication changed and a email sent out to all those on the booking system to warn them about possible phishing scam.

Whilst this would expose the hotel's security flaws, it would at least protect the consumer.

But booking .com don't have any such procedure in place and thus I will never use them
 
Back
Top